Security headers grade
Six short lines in a server response tell the browser how careful to be with your page. This check reads them, scores them out of 100 and writes the missing ones for you.
Headers are instructions, not content
Every time a browser asks for a page, the server answers in two parts. The second part is the page itself. The first is a list of headers, short name-and-value lines the visitor never sees, such as the type of file, how long to cache it, and which cookies to keep.
A handful of those lines are security instructions. They don’t make your server any harder to break into. They switch on protections that every modern browser already has built in, and that stay off until a site asks for them. A site that sends none of them still works fine. It’s just leaving free armor in the box.
The six headers this check scores
| Header | Points | What it prevents |
|---|---|---|
Strict-Transport-Security | 25 | A visitor being quietly downgraded to unencrypted http:// on hostile Wi-Fi. After the first visit, the browser refuses plain HTTP for your domain for as long as max-age says. |
Content-Security-Policy | 25 | Injected scripts. You publish the list of places code may load from, and anything else is blocked, even if an attacker manages to slip a <script> tag into a comment or a form field. |
X-Frame-Options | 15 | Clickjacking, where another site loads yours in an invisible frame and tricks people into pressing your buttons. The modern equivalent is frame-ancestors inside the CSP, which this check accepts too. |
X-Content-Type-Options | 15 | Type guessing. With nosniff, a file uploaded as an image can’t be run as a script because the browser “thought it looked like one”. |
Referrer-Policy | 10 | Leaking full page addresses, including anything private in the URL, to every site you link to. |
Permissions-Policy | 10 | Embedded third-party content asking for the camera, microphone or location under your name. |
The weights follow how much damage each one prevents. The two 25-point headers stop the attacks that really empty accounts. The 10-point ones are about privacy and good manners.
How to read the grade
A header only counts in full when its value does the job. Three situations earn partial credit:
- HSTS shorter than six months. A one-day
max-ageis fine while you’re testing, but it protects returning visitors for one day. - A CSP that allows
'unsafe-inline'or'unsafe-eval'without nonces or hashes. That’s the very door the policy was supposed to close. - A CSP in
Report-Onlymode. It observes and reports but blocks nothing yet. That’s the right first step, as long as you don’t stop there.
The check also lists each cookie the page sets and whether it carries Secure, HttpOnly and SameSite. Those flags aren’t in the score, but a session cookie without them undoes much of what the headers achieve.
An A here means the browser-side protections are switched on for this one response. It says nothing about passwords, plugins or server patches. Different pages of the same site can also send different headers, so test the pages that matter: login, checkout, account.
Where to add them
Headers are set wherever responses are produced, and the layer closest to the visitor wins:
- A CDN or proxy (Cloudflare, Fastly, a host’s edge)
- Usually a “response header” or “transform” rule in the dashboard. One rule covers the whole site, cached pages included.
- Apache
- In
.htaccessor the virtual host:Header always set X-Content-Type-Options "nosniff". The wordalwaysmakes it apply to error pages too. - nginx
add_header X-Content-Type-Options "nosniff" always;in theserverblock. Watch out for one thing: anadd_headerinside alocationblock replaces the ones above it, it doesn’t add to them.- The application
- Frameworks and CMS plugins can send headers, but only on pages they generate. Static files served directly by the web server will miss them.
Start with the four that can’t break anything: nosniff, X-Frame-Options: SAMEORIGIN, a Referrer-Policy and a Permissions-Policy. Add HSTS once every subdomain works over HTTPS. Leave the Content-Security-Policy for last and roll it out in report-only mode first, because a wrong CSP will block your own scripts.
Questions people ask
Will adding security headers break my site?
Four of the six are safe to add without looking. The two that need care are HSTS and Content-Security-Policy. HSTS locks visitors to HTTPS for the duration you set, so every subdomain must already have a valid certificate if you use includeSubDomains. A CSP blocks anything that isn’t on your list. Test it with Content-Security-Policy-Report-Only for a week or two before enforcing it.
Do security headers help SEO?
Not directly. Search engines don’t rank pages by their headers. HTTPS is a light ranking signal, and HSTS makes HTTPS stick. What you really gain is fewer hacked pages, and a hacked site loses rankings fast.
Why is X-XSS-Protection not in the list?
Browsers removed the filter it controlled. Chrome dropped it in 2019 and Firefox never had it. The current advice is to leave it out or set it to 0, and rely on a Content-Security-Policy instead.
What max-age should HSTS use?
One year (max-age=31536000) is the usual target and the minimum for browser preload lists. Start with a few minutes, check that nothing breaks, then raise it in steps. This check gives full marks from six months up.
My site is behind Cloudflare. Whose headers are these?
The ones the visitor receives, and those are the ones that matter. If your origin server sets a header and the CDN strips or overrides it, the grade reflects the CDN’s version.